LWA-2026-5816 MAL-2026-6370 ↗ confirmed malware

hyperpure@1.0.0

Malicious code in hyperpure (npm)

T1195.002 · Compromise Software Supply ChainT1059.004 · Unix ShellT1082 · System Information DiscoveryT1552 · Unsecured CredentialsT1071.001 · Web ProtocolsT1041 · Exfiltration Over C2 Channel

Analysis

hyperpure@1.0.0 masquerades as a legitimate supply-chain library (impersonating Zomato's Hyperpure brand) but is a malicious package that performs system reconnaissance and environment-variable theft at install time. The preinstall hook runs a curl command that sends the system hostname, username, working directory, and the ENTIRE environment (base64-encoded) to hxxp://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7[.]oast[.]site/install/<base64>. The preuninstall hook also sends the hostname to the same C2 at /uninstall/hyperpure. The package itself provides zero functional code (a single 58-byte stub). The stolen environment variables can include npm/GitHub/AWS tokens, API keys, and other credentials available to the installing user.

analyzed by
Leitwacht
first seen
Jun 21, 2026, 03:44 PM
analyzed
Jun 21, 2026, 03:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.